1-2
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring the ASA for Cisco Cloud Web Security
Information About Cisco Cloud Web Security
This chapter includes the following sections:
•
Information About Cisco Cloud Web Security, page 1-2
•
Licensing Requirements for Cisco Cloud Web Security, page 1-6
•
Prerequisites for Cloud Web Security, page 1-7
•
Guidelines and Limitations, page 1-7
•
•
Configuring Cisco Cloud Web Security, page 1-8
•
Monitoring Cloud Web Security, page 1-16
•
Configuration Examples for Cisco Cloud Web Security, page 1-17
•
•
Feature History for Cisco Cloud Web Security, page 1-25
Information About Cisco Cloud Web Security
This section includes the following topics:
•
Redirection of Web Traffic to Cloud Web Security, page 1-2
•
User Authentication and Cloud Web Security, page 1-2
•
•
•
Cloud Web Security Actions, page 1-5
•
Bypassing Scanning with Whitelists, page 1-5
•
IPv4 and IPv6 Support, page 1-6
•
Failover from Primary to Backup Proxy Server, page 1-6
Redirection of Web Traffic to Cloud Web Security
When an end user sends an HTTP or HTTPS request, the ASA receives it and optionally retrieves the
user and/or group information. If the traffic matches an ASA service policy rule for Cloud Web Security,
then the ASA redirects the request to the Cloud Web Security proxy servers. The ASA acts as an
intermediary between the end user and the Cloud Web Security proxy server by redirecting the
connection to the proxy server. The ASA changes the destination IP address and port in the client
requests and adds Cloud Web Security-specific HTTP headers and then sends the modified request to the
Cloud Web Security proxy server. The Cloud Web Security HTTP headers include various kinds of
information, including the username and user group (if available).
User Authentication and Cloud Web Security
User identity can be used to apply policy in Cloud Web Security. User identity is also useful for Cloud
Web Security reporting. User identity is not required to use Cloud Web Security. There are other methods
to identify traffic for Cloud Web Security policy.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......